7.5
CVSSv3

CVE-2023-22915

Published: 24/04/2023 Updated: 04/05/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A buffer overflow vulnerability in the “fbwifi_forward.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 up to and including 5.35, USG FLEX 50(W) firmware versions 4.30 up to and including 5.35, USG20(W)-VPN firmware versions 4.30 up to and including 5.35, and VPN series firmware versions 4.30 up to and including 5.35, which could allow a remote unauthenticated malicious user to cause DoS conditions by sending a crafted HTTP request if the Facebook WiFi function were enabled on an affected device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zyxel usg_flex_100_firmware

zyxel usg_flex_100w_firmware

zyxel usg_flex_200_firmware

zyxel usg_flex_50_firmware

zyxel usg_flex_50w_firmware

zyxel usg_flex_500_firmware

zyxel usg_flex_700_firmware

zyxel vpn100_firmware

zyxel vpn1000_firmware

zyxel vpn300_firmware

zyxel vpn50_firmware

zyxel usg_20w-vpn_firmware